terminal-ops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent ingests untrusted data from external sources and performs sensitive actions based on that data.
- Ingestion points: The agent is instructed to read "logs", "command output", "git state", and "repo files" during the 'Read the failing surface first' phase (SKILL.md).
- Boundary markers: The instructions lack explicit boundary markers or directives to ignore instructions that might be embedded within the external files or logs being analyzed.
- Capability inventory: The skill allows the agent to execute arbitrary terminal commands, modify the filesystem, and push changes to remote repositories (SKILL.md).
- Sanitization: There are no documented steps for sanitizing or validating external input before it influences the agent's actions or commands.
Audit Metadata